# Data Inventory & Classification Policy

| Version | Effective | Approved | Last reviewed | Owner |
|---|---|---|---|---|
| 1.4 | October 2, 2026 | October 2, 2026 | October 2, 2026 | Brian Johnson, President |

!!!info About This Document
This policy defines how 7 Minute Security LLC inventories, classifies, and handles data based on its sensitivity. It ensures every piece of data we hold is known, labeled, and protected appropriately.
!!!

## 1. Purpose

You can't protect what you don't know you have. This policy establishes how 7MinSec identifies, inventories, and classifies the data it holds, and defines the handling requirements for each classification level.

## 2. Scope

This policy applies to all data created, received, processed, stored, or transmitted by 7MinSec, regardless of format (digital or physical) or location (cloud, local, or endpoint).

## 3. Data Classification Levels

| Classification | Definition | Examples |
|---|---|---|
| Level 1: Public | Information approved for public release with no restrictions | Marketing materials, Trust Center policies, published blog posts |
| Level 2: Internal | Non-sensitive business information for internal use only | Internal procedures, vendor lists, meeting notes |
| Level 3: Confidential | Sensitive business or client information; unauthorized disclosure would cause harm | Client reports, assessment findings, subcontractor agreements, business financials |
| Level 4: Restricted | Highly sensitive data; disclosure could cause significant harm or legal liability | Client credentials (during testing), raw vulnerability data, PII, authentication secrets |

When in doubt, classify data at the higher level. Reclassification requires approval from Brian Johnson (President).

## 4. Data Inventory

| Data Type | Classification | Primary Location | Retention Period |
|---|---|---|---|
| Client contact information | Level 2: Internal | Productivity suite (email/contacts) | Duration of relationship + 3 years |
| Active engagement working files | Level 3: Confidential | Cloud file storage (access-restricted) | 60 days post-engagement, then purged |
| Penetration test raw output & notes | Level 4: Restricted | Cloud file storage, report authoring platform, or vulnerability scanning host (all access-restricted) | 60 days post-engagement, then purged |
| Client credentials (during testing) | Level 4: Restricted | Password manager (dedicated vault) | Deleted immediately at engagement close |
| Final report deliverables | Level 3: Confidential | Cold storage archive | 3 years, then securely deleted |
| Subcontractor partnership agreements | Level 3: Confidential | Productivity suite / secure storage | Duration of relationship + 3 years |
| 7MinSec internal credentials | Level 4: Restricted | Password manager | Active, rotated per access policy |
| Marketing and public content | Level 1: Public | 7MinSec website / productivity suite | Indefinite |

## 5. Handling Requirements by Classification

Requirements are cumulative. Each level carries every requirement of the levels below it, plus its own.

### 5.1 Level 1: Public

- No special handling required
- May be freely shared externally

### 5.2 Level 2: Internal

- Share only with 7MinSec personnel and subcontractors on a need-to-know basis
- Store in 7MinSec-managed systems (productivity suite, cloud file storage)

### 5.3 Level 3: Confidential

- Access restricted to personnel directly involved in the relevant engagement
- Must be transmitted as expiring, password-protected, encrypted links, never as email attachments
- Must be stored in access-controlled locations (cloud file storage with restricted sharing, the report authoring platform, or cold storage)
- Must be encrypted at rest
- Labeled "CONFIDENTIAL" on documents where practical

### 5.4 Level 4: Restricted

- Access limited to the minimum number of personnel required
- Client credentials stored exclusively in a dedicated password manager vault and deleted at engagement close
- Raw vulnerability data stored on the report authoring platform (address-restricted), on the self-hosted vulnerability scanning host (network-isolated), or in cloud file storage with strict access controls
- Never transmitted via email under any circumstances
- Never stored on unmanaged or personal devices beyond the duration of active work
- Must be encrypted at rest
- Where transmission is unavoidable, use the same expiring, password-protected encrypted links required at Level 3
- Labeled "RESTRICTED" on all documents

## 6. Approved Storage Platforms

| Platform | Purpose | Approved Classification |
|---|---|---|
| Cloud productivity suite | Internal email, calendar, business documents | Levels 1 to 3 |
| Cloud file storage | Active engagement working files | Levels 1 to 3 (Level 4 only in restricted-access folders) |
| Report authoring platform (self-hosted, address-restricted) | Penetration test report authoring and raw findings | Levels 3 and 4 |
| Vulnerability scanning host (self-hosted, network-isolated) | Authenticated and external vulnerability scanning, and the raw scan output it produces | Level 4 |
| Enterprise password manager | All credential storage | Level 4 |
| Cold storage archive | Long-term report retention | Level 3 |
| Encrypted, expiring link delivery | Secure delivery of reports and credentials to clients | Levels 3 and 4 (transmission only) |

Storing 7MinSec or client data on unapproved platforms (personal cloud storage, USB drives, personal email, etc.) is prohibited without explicit approval from Brian Johnson (President). Subcontractor data handling obligations are established in the 7MinSec Partnership Agreement and reaffirmed annually via the Subcontractor Security Acknowledgment form.

## 7. Data Disposal

When data reaches the end of its retention period, it must be disposed of securely:

- Digital files: secure deletion using approved tools (file shredding / verified overwrite)
- Cloud storage: permanent deletion confirmed (emptying trash/recycle bin)
- Credentials: revoked and deleted from the password manager, not just archived

Disposal is logged for Level 3 and Level 4 data.

## 8. Policy Review

This policy and the data inventory table are reviewed annually, or whenever a new data category, platform, or significant business change occurs. The current version is published in the [7MinSec Trust Center](https://kb.7minsec.com/trust).

!!!info Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
!!!

## Change Log

This log records all changes made to this policy over time.

| Version | Date | Author | Description of Change |
|---|---|---|---|
| 1.0 | September 1, 2026 | Brian Johnson | Initial release. |
| 1.1 | September 23, 2026 | Brian Johnson | No substantive change. Version aligned with the rest of the policy suite following the September 2026 review. |
| 1.1.1 | September 24, 2026 | Brian Johnson | Editorial pass ahead of publication: em dashes removed throughout, including from the classification level labels, which now read Level 1: Public and so on. No requirement, classification, or retention period changed. |
| 1.2 | September 28, 2026 | Brian Johnson | Reviewed by an independent assessor against the CIS Controls with no changes required. Version aligned with the rest of the policy suite. |
| 1.3 | October 2, 2026 | Brian Johnson | Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. Added the self-hosted vulnerability scanning host as an approved Level 4 location in Sections 4, 5.4 and 6, carrying the same 60 day post-engagement purge as other raw output. Raw scan output of client environments was already held there, which Sections 5.4 and 6 did not permit. Corrected the approved platforms table so the expiring encrypted link service shows Levels 3 and 4 for transmission, matching Section 5.4, which already permitted Level 4 transmission where unavoidable. |
| 1.4 | October 2, 2026 | Brian Johnson | No change to this policy. Version aligned with the rest of the suite. |

!!!info Document Feedback
To suggest changes to this policy or report an issue, contact: [security@7minsec.com](mailto:security@7minsec.com)
!!!

*Last reviewed: October 2, 2026*
